Courseiva
Infrastructure Security →easyMultiple Select

SCS-C02 Infrastructure Security Practice Question

A Security Engineer is designing a secure VPC architecture. Which THREE components are essential for creating a public subnet that can host a web server accessible from the internet?

⚠ Common exam trap

Test-takers frequently confuse a NAT Gateway with an Internet Gateway, mistakenly thinking a NAT Gateway can provide inbound internet access to a public subnet, when in fact it only supports outbound traffic from private subnets.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Route table with a default route (0.0.0.0/0) pointing to the IGW

A public subnet requires a route table that directs traffic destined for 0.0.0.0/0 to an Internet Gateway (IGW). Without this default route, instances in the subnet cannot send or receive traffic from the internet, even if they have public IP addresses. The IGW acts as the target for this route, enabling bidirectional communication between the VPC and the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPN connection to on-premises

    Why it's wrong here

    A VPN connection to on-premises is unrelated to enabling internet connectivity for a public web subnet. VPNs create an encrypted IPsec tunnel to an on-premises network for hybrid cloud communication, not for internet egress or ingress. In this architecture, web traffic still must travel through an Internet Gateway and associated route tables; the VPN would only route traffic destined for your on-premises CIDR ranges, so it cannot replace the IGW or default route.

  • ✓

    Route table with a default route (0.0.0.0/0) pointing to the IGW

    Why this is correct

    A route table entry for 0.0.0.0/0 targeting the Internet Gateway (IGW) is the core routing mechanism that makes a subnet public. Without this default route, the IGW exists but traffic from the subnet cannot reach it; the VPC's implicit local route only handles VPC-internal traffic. This route is required for the web server to receive inbound HTTP/HTTPS from the internet and to send responses back, making it a mandatory component of a public subnet design.

  • ✓

    Security group allowing inbound HTTP/HTTPS from 0.0.0.0/0

    Why this is correct

    A security group rule allowing inbound HTTP (port 80) and HTTPS (port 443) from 0.0.0.0/0 is a stateful firewall filter that permits internet clients to initiate connections to the web server. This rule is necessary to protect the instance, but it is not a routing construct; it only controls traffic that is already routed to the instance via the subnet's route tables. The security group works at the instance level and does not replace the IGW or the default route, so while it is a correct and necessary component, it would be ineffective without the route table configuration.

  • ✗

    NAT Gateway

    Why it's wrong here

    A NAT Gateway is designed for private subnets to initiate outbound internet traffic while remaining unreachable from the internet. Since the goal is to expose a web server to inbound HTTP/HTTPS from the public internet, a NAT Gateway is incorrect because it does not support inbound connections from the internet and requires a route table entry pointing to an IGW for its own outbound traffic. Adding a NAT Gateway would add cost and complexity but would not provide the needed public inbound path.

  • ✓

    Internet Gateway (IGW)

    Why this is correct

    An Internet Gateway (IGW) is the horizontally scaled, redundant VPC component that provides a target for internet traffic and performs NAT for instances with public IPs. However, the IGW alone is insufficient; the subnet's route table must contain a default route (0.0.0.0/0) pointing to the IGW for traffic to flow. The IGW is a necessary foundation, but the route association is the enabling configuration that makes the subnet public, so both are required for a complete public web architecture.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This SCS-C02 question is part of Courseiva's 1,205-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.